Junglewise Threat Intelligence

CVE-2026-18460: RTI Connext Professional off-by-one error in core libraries

CVE-2026-18460 · Severity: info · Published 2026-09-22

Technologies: Rti Connext Professional. Vendors: Rti.

Executive brief

RTI Connext Professional is middleware that enables real-time data distribution and communication between networked applications. An off-by-one error in the core libraries allows attackers to write data out-of-bounds in memory, potentially causing application crashes, data corruption, or arbitrary code execution depending on memory layout and exploit conditions.

Technical details

An off-by-one error in RTI Connext Professional's core libraries permits out-of-bounds write operations, leading to buffer overflow. The vulnerability affects versions 7.0.0 before 7.3.1.6 and 7.4.0 before 7.7.0.1. Exploitation requires network access to a Connext endpoint but no authentication; patched versions are available.

Affected products

  • RTI Connext Professional 7.0.0 before 7.3.1.6, 7.4.0 before 7.7.0.1

Timeline

  • 2026-09-22: disclosed

References

Related threats